Hierarchical Network Control System for Public Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public datacenters often lack robust and transparent security capabilities, making companies hesitant to move their networks into these environments due to the inability to exercise direct security control over virtualization software and forwarding elements.
Innovation Solution
A hierarchical network control system that manages logical networks across private and public datacenters by operating network controllers and managed forwarding elements within virtual machines in public datacenters, enabling the enforcement of network security and forwarding rules through a gateway controller and local control agents, and utilizing distributed network encryption for secure traffic management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If companies move their networks to public datacenters to reduce costs and physical server burdens, then cost and maintenance burden are reduced, but security control capability deteriorates because the public datacenter owner controls the virtualization software and forwarding elements
Solution Approach 1:
The patent introduces a network control system as an intermediary layer between the public datacenter infrastructure and the customer's network workloads. This control system includes controllers that manage forwarding elements and security policies, acting as a mediator that enables customers to exercise security control without directly managing the underlying virtualization software controlled by the public datacenter owner.
2Adaptability or versatility
If the network control system operates without access to virtualization software in public datacenters, then deployment flexibility is improved, but security policy enforcement capability deteriorates
Solution Approach 1:
The control system uses intermediary components including controllers that communicate with forwarding elements through standardized interfaces, and security policies that are enforced at the forwarding element level without requiring direct access to virtualization software. This intermediary architecture enables deployment flexibility while maintaining security policy enforcement.
Solution Approach 2:
The patent segments the network control functionality into separate components: controllers that manage policy and configuration, forwarding elements that handle packet processing, and security modules that enforce policies. This segmentation allows the control system to operate independently of the virtualization software while maintaining comprehensive security control.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Some embodiments provide a method for a first network controller that manages a logical network implemented in a datacenter including forwarding elements to which the first network controller does not have access. The method identifies a first data compute node (DCN) in the datacenter configured to execute a second network controller. The method distributes configuration data defining the logical network to the first DCN. The second network controller distributes sets of the configuration data to local agents executing on additional DCNs in the datacenter that send and receive messages through the logical network. Both managed forwarding elements and the local agents execute on each of the additional DCNs. Each local agent on a particular DCN is for receiving a set of configuration data from the second network controller and configuring the managed forwarding element on the particular DCN to implement the logical network according to the set of configuration data.